Extension WordPress
Vulnérabilités OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA)
Cette page rassemble les failles publiées pour OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA)
4 fiches
OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) <= 1.2.62 – Unauthenticated Stored Cross-Site Scripting
The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.62 due to insufficient input sanitization and output escaping. This makes…
*-1.2.62
1.2.63
23/03/2026
OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) <= 1.2.53 – Unauthenticated IP Header Spoofing
The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to IP Header Spoofing in all versions up to, and including, 1.2.53. This is due to the plugin trusting client-controlled forwarded…
*-1.2.53
1.2.54
30/10/2025
OOPSpam Anti-Spam <= 1.1.44 – Cross-Site Request Forgery via empty_ham_entries and empty_spam_entries
The OOPSpam Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.44. This is due to missing or incorrect nonce validation on the 'empty_ham_entries' and 'empty_spam_entries' functions. This makes it possible…
[*, 1.1.45)
1.1.45
21/06/2023
OOPSpam Anti-Spam <= 1.1.35 – Authenticated (Admin+) Stored Cross-Site Scripting
The OOPSpam Anti-Spam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via options such as 'oopspam_wpregister_spam_message', 'oopspam_woo_spam_message', and 'oopspam_give_spam_message' (as well as numerous others) in versions up to, and including, 1.1.35 due to insufficient input sanitization and…
*-1.1.35
1.1.36
17/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.